CVE-2016-5995

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
01/10/2016
Last modified:
12/04/2025

Description

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:advanced_workgroup:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:express:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:workgroup:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:advanced_workgroup:*:*:*